PT-2026-57217 · Grav · Grav
CVE-2026-53653
·
Published
2026-07-10
·
Updated
2026-08-14
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Grav versions prior to 1.7.53
Grav versions prior to 2.0.0-rc.8
Description
An unauthenticated visitor can cause server memory and CPU exhaustion by requesting image derivatives with oversized dimensions. This occurs through URL query image actions, such as
forceResize in the Grav::fallbackUrl function, which passes request parameters to ImageMedium magic actions without enforcing a dimension or pixel ceiling.Recommendations
Update Grav to version 1.7.53 or later.
Update Grav to version 2.0.0-rc.8 or later.
Exploit
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Grav